Simulating data breaches: Synthetic datasets for depicting personally identifiable information through scenario-based breaches

模拟数据泄露:通过基于场景的泄露事件来描述个人身份信息的合成数据集

阅读:1

Abstract

With hackers relentlessly disrupting cyberspace and the day-to-day operations of organizations worldwide, there are also concerns related to Personally Identifiable Information (PII). Due to the data breaches and the data getting dumped on the clear web or the dark web, there are serious concerns about how the different threat actors worldwide can misuse the data. Also, it raises the question of how hackers can create a profile of an individual starting from one data leak and getting more details on individuals with the help of Open Source Intelligence (OSINT). Furthermore, there is a dilemma in utilizing data breach datasets dumped on the clear web or the dark web because of the sensitive nature of the information. There can be issues related to ethics, law enforcement, and legal use of data. Thus, to tackle this, we will construct synthetic datasets that will allow researchers and professionals to understand how data leaks can be dangerous and how hackers can connect the dots further by creating complete profiles of individuals. We have programmatically generated a synthetic master record of 4 million unique individuals with complete profiles of their PIIs, and then using the master record, we have further generated 16 scenario-based datasets by creating a fictitious narrative of data breaches covering different industry types. These datasets will facilitate researchers and industry professionals in understanding the distribution of PIIs across data breaches. The data classes represent the nature of PIIs sourced from 'Have I Been Pwned?' to create synthetic records. The synthetically generated records are shared with the code in this paper to facilitate future researchers and practitioners to generate customized synthetic records according to their requirements, enabling transparency in terms of reusability, reproducibility, and replicability.

特别声明

1、本页面内容包含部分的内容是基于公开信息的合理引用;引用内容仅为补充信息,不代表本站立场。

2、若认为本页面引用内容涉及侵权,请及时与本站联系,我们将第一时间处理。

3、其他媒体/个人如需使用本页面原创内容,需注明“来源:[生知库]”并获得授权;使用引用内容的,需自行联系原作者获得许可。

4、投稿及合作请联系:info@biocloudy.com。